I-Worm.Scorpion
Description I-Worm.Scorpion
This is a dangerous worm that spreads via the Internet in infected e-mails. The worm itself is a Windows application written in Delphi and about 370K in size. Upon being executed (by clicking on the attached file, for instance), it installs itself into the system, registers itself as a service process (hidden application), then sends infected messages (with its attached copy), and, depending on the system date, runs its payload routine. Installation to System The worm copies itself to the Windows system directory with a name randomly selected from the following variants: Play.exe Bigs as.exe Zorro.exe Honey.exe Jefes.exe Corte de pelo.exe Tangas.exe Canibal.exe Picadita.exe Josefina.exe and registers that file in the Registry auto-run key: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun Scorpion=%filename% E-mail Spreading The worm sends itself from infected machines as an attached file with random names as above, and with the Subject and message Body randomly selected from the following variants: Subjects: Sorpresa !!! Este si que es un buen presente Diviertanse Todo debe estar limpio Echale un ojo a esto Buena PECHOnalidad Con todo mi aprecio El aguijon de Scorpion Traseros Mujeres Message body: Abrelo sin miedo que, no es ningun Virus No tiene ningun Virus Abrelo no hay PELIGRO, esta limpio de Virus Mira que bueno esta esto Espero que esto te guste Scorpion hace de las suyas Esto si esta interesante abrelo que no hay peligro Dime si te gusto No tiene Virus, asi que abranlo y disfrutenlo Observa el gran poder de las mujeres en su parte trasera To send infected messages, the worm connects to a SMTP server. The worm obtains the name of the SMTP server from the default-system settings. A victim's e-mail addresses are obtained from the WAB file (Windows Address Book). The messages also are sent each time to: jajachistes@topica.com tavojaja@yahoogroups.com cartones@egroups.com pensamientos@egroups.com huateque@egroups.com jacastro@geoline.net forodelphi2000@yahoo.com.ar The worm sends e-mails immediately upon the first start-up, then in time intervals, depending on its internal time counters. Payloads and other The worm finds and deletes all *.INF and *.SYS files on a drive where Windows is installed, and the system is destroyed due to this in most cases. Starting in September, and the 15th of each month, the virus runs itself with some video effect. The worm also creates and modifies the following registry keys: HKEY_LOCAL_MACHINESoftwareScorpionHelp Mail = Negro Fack = Rojo These keys indicate that: 1st key - e-mail messages have already been sent; 2nd key - INI and SYS files have been deleted. Depending on its internal time counters, the worm also closes all active application windows, opens/closes the CD drive, blinks the Num/Caps/Scroll-lock keys, an displays 500 messages: Scorpion ya está aquí !!!!
Check other viruses! Be aware! Use Antiviral Software
Guppy.152.a
Description Guppy.152.a
It is a memory resident harmless virus. It infects COM-files which begin from JMP command (E9 xx xx ) only. The first infected program is not running because the virus stays memory resident together with it and doesn't give the control back to the infected program. The infector hooks INT 21h.
GV Family
Description GV Family
These are not dangerous memory resident parasitic viruses. They hook INT 9, 16h, 21h, 28h and write themselves to the end of COM-files that are executed. On pressing of Alt-Ctrl-V keys they display the messages: "GV.2856": +--------------------------------+ ¦ Good Virus #1 Alpha Model ¦ ¦ [GV1] ¦ ¦ (c) 1994 by Stormbringer [P/S] ¦ ¦ ¦ ¦ Infection Mode: ¦ ¦ [N]one ¦ ¦ [I]nfect Files ¦ ¦ [D]isinfect Files ¦ ¦ ¦ ¦ Encryption Commands: ¦ ¦ [E]ncrypt File ¦ ¦ De[C]rypt File ¦ ¦ ¦ ¦ Press [ESC] To Exit Menu ¦ +--------------------------------+
"GV.2865": +--------------------------------+ ¦ Good Virus #1 1.01 ¦ ¦ [GV1] ¦ ¦ (c) 1994 by Stormbringer [P/S] ¦ ¦ ¦ ¦ Infection Mode: ¦ ¦ [N]one ¦ ¦ [I]nfect Files ¦ ¦ [D]isinfect Files ¦ ¦ ¦ ¦ Encryption Commands: ¦ ¦ [E]ncrypt File ¦ ¦ De[C]rypt File ¦ ¦ ¦ ¦ Press [ESC] To Exit Menu ¦ +--------------------------------+
When the 'D' key is pressed they disinfect the infected files on their execution. When the 'E' or 'C' keys are pressed they encrypt/decrypt the file which is selected by the user. The viruses display the messages before encryption: +-[Enter Filename Below]-+ ¦ > ¦ +------------------------+ +----[Please Enter 16 Byte Password (Extra Chars Ignored)]----+ ¦ > ¦ +-------------------------------------------------------------+
They also contain/display the internal strings: "GV.2856": Good Virus #1 Alpha (c) 1994 Stormbringer [P/S] Now Loaded. Press CTRL-ALT-V For User Menu. Infection Set To NONE. Error Opening File! GV1 GoodVir1
"GV.2865": Error Opening File! GV1 v101
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
American Pit Bull Long Layered Haircuts Classic Boys Hairstyles Windows 7 Key Jessica Biel Photo
|